Results 1 to 10 of 91

Thread: Malware Infection

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Member
    Join Date
    Jul 2010
    Posts
    47

    Default Malware Infection

    My Spybot S&D is showing that I have been infected with Win32.agent.ieu

    Here is the DDS log.


    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Darlin at 13:40:46.40 on 12/07/2010
    Internet Explorer: 7.0.6002.18005
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1478 [GMT -4:00]

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\SMINST\BLService.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Eropea.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\conime.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Users\Darlin\Downloads\dds.scr
    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.ca/
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
    uSearch Page =
    uSearch Bar =
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
    uInternet Settings,ProxyOverride = <local>;*.local
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
    uRun: [Google Update] "c:\users\darlin\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [pacqwen] rundll32 "c:\users\darlin\appdata\roaming\nb-NOM.dll",UDPNTWWWQJ
    uRun: [JDK5SWFMZY] c:\users\darlin\appdata\local\temp\Ez1.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [PopRock] c:\users\darlin\appdata\local\temp\a.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [FBSSA] c:\program files\sgpsa\ie3sh.exe
    mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
    mRun: [SweetIM] c:\program files\sweetim\messenger\SweetIM.exe
    mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
    mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
    mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
    mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
    StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
    StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\users\darlin\appdata\roaming\microsoft\windows\start menu\programs\startup\wwwxbv32.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: {612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\xmlbar\youku downloader\YoukuDownloader(xmlbar).exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
    IFEO: image file execution options - svchost.exe
    IFEO: a.exe - svchost.exe
    IFEO: aAvgApi.exe - svchost.exe
    IFEO: AAWTray.exe - svchost.exe
    IFEO: About.exe - svchost.exe

    Note: multiple IFEO entries found. Please refer to Attach.txt

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - search
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
    FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
    FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
    FF - plugin: c:\users\darlin\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
    R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-11 361808]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-11 193840]
    R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\google\update\GoogleUpdate.exe [2009-9-3 133104]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== Created Last 30 ================

    2010-07-12 16:25:33 0 d-----w- c:\program files\Safer Networking
    2010-07-12 13:25:28 8 ----a-w- c:\users\darlin\appdata\roaming\vdnxlf.dat
    2010-07-12 13:25:24 4 ----a-w- c:\users\darlin\appdata\roaming\avdrn.dat
    2010-07-12 03:08:05 255227926 ----a-w- c:\windows\MEMORY.DMP
    2010-07-12 01:05:43 0 d-----w- c:\program files\CCleaner
    2010-07-11 23:58:21 0 d-----w- c:\program files\Microsoft Security Essentials
    2010-07-11 23:54:59 0 d-----w- c:\program files\TweetDeck
    2010-07-11 21:46:31 88 ----a-w- c:\windows\wininit.ini
    2010-07-11 21:16:36 0 d-----w- c:\programdata\Spybot - Search & Destroy
    2010-07-11 21:16:36 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-07-11 20:03:40 206336 ----a-w- c:\windows\Eropea.exe
    2010-07-11 18:14:26 0 d-sh--w- c:\programdata\SMACCEEAV
    2010-07-10 03:20:48 88576 --sha-r- c:\users\darlin\appdata\roaming\nb-NOM.dll
    2010-07-01 03:07:30 0 d-----w- c:\users\darlin\dwhelper
    2010-06-23 16:25:13 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2010-06-23 16:25:13 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2010-06-23 16:25:13 297808 ----a-w- c:\windows\system32\mscoree.dll
    2010-06-23 16:25:13 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2010-06-23 16:25:13 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2010-06-22 23:32:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2010-06-22 23:32:16 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2010-06-20 19:29:53 0 d-----w- c:\program files\iPod
    2010-06-20 19:29:48 0 d-----w- c:\program files\iTunes
    2010-06-20 19:24:01 0 d-----w- c:\program files\Bonjour
    2010-06-14 17:32:43 0 d-----w- c:\programdata\LightScribe

    ==================== Find3M ====================

    2010-07-12 17:29:44 31966 ----a-w- c:\programdata\nvModes.dat
    2010-06-25 15:20:20 62236 ----a-w- c:\windows\system32\perfh00C.dat
    2010-06-25 15:20:20 19286 ----a-w- c:\windows\system32\perfc00C.dat
    2010-06-20 19:25:57 86016 ----a-w- c:\windows\inf\infstor.dat
    2010-06-20 19:25:57 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-06-20 19:25:56 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-06-01 17:37:48 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
    2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
    2010-05-18 20:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-05-18 20:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-05-04 19:15:20 834048 ----a-w- c:\windows\system32\wininet.dll
    2010-05-04 18:37:45 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-05-01 14:13:48 2037248 ----a-w- c:\windows\system32\win32k.sys
    2010-04-30 02:15:22 665600 ----a-w- c:\windows\inf\drvindex.dat
    2010-04-28 14:25:59 97420 ----a-w- c:\windows\fonts\leelawdb.ttf
    2010-04-27 21:28:06 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
    2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
    2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
    2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
    2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
    2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
    2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2010-03-10 23:05:08 59232800 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2008-08-11 10:58:25 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 13:42:56.27 ===============

  2. #2
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default




    Please read Before You Post
    While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

    You do have some issue going on , the infections you picked up are most likely from using programs like Limewire Read this please
    http://forums.spybot.info/showthread.php?t=282

    Its advisable to remove Limewire via Programs and Features in the Control Panel.





    Download ComboFix from one of these locations:

    Link 1
    Link 2


    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    • See this Link for programs that need to be disabled and instruction on how to disable them.
    • Remember to re-enable them when we're done.

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

    *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  3. #3
    Member
    Join Date
    Jul 2010
    Posts
    47

    Default

    Thank you for helping me. I uninstalled Limewire. I ran combofix. I have attached the requested ComboFix.txt file. Hope to hear from you soon.

    ComboFix 10-07-16.01 - Darlin 17/07/2010 20:53:51.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1866 [GMT -4:00]
    Running from: c:\users\Darlin\Desktop\ComboFix.exe
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\users\Bhing or J.A\.COMMgr
    c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}
    c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\chrome.manifest
    c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\chrome\content\_cfg.js
    c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\chrome\content\overlay.xul
    c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\install.rdf
    c:\users\Darlin\AppData\Roaming\avdrn.dat
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\CLSV.sys
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\dudl.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\FS.dll
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\FS.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\FW.exe
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\gid.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\pal.tmp
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\SM.tmp
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwwxbv32.exe
    c:\windows\system32\system

    .
    ((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
    .

    2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\TEMP\AppData\Local\temp
    2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\TEMP.Darlin-PC\AppData\Local\temp
    2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\TEMP.Darlin-PC.000\AppData\Local\temp
    2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\Guest\AppData\Local\temp
    2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\Bhing or J.A\AppData\Local\temp
    2010-07-12 16:25 . 2010-07-12 16:25 -------- d-----w- c:\program files\Safer Networking
    2010-07-12 13:25 . 2010-07-12 13:25 -------- d-----w- c:\windows\Sun
    2010-07-12 01:05 . 2010-07-12 01:05 -------- d-----w- c:\program files\CCleaner
    2010-07-11 23:54 . 2010-07-11 23:54 -------- d-----w- c:\program files\TweetDeck
    2010-07-11 21:16 . 2010-07-12 01:18 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2010-07-11 21:16 . 2010-07-11 21:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-07-11 18:14 . 2010-07-11 18:14 -------- d-sh--w- c:\programdata\SMACCEEAV
    2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
    2010-07-01 03:07 . 2010-07-01 03:07 -------- d-----w- c:\users\Darlin\dwhelper
    2010-06-29 20:36 . 2010-06-14 16:08 103424 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
    2010-06-29 20:36 . 2010-06-14 16:08 4687872 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
    2010-06-29 20:36 . 2010-06-14 16:08 545280 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
    2010-06-29 20:36 . 2010-06-14 16:08 4687360 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
    2010-06-29 20:36 . 2010-06-14 16:08 425984 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
    2010-06-29 20:36 . 2010-06-14 16:08 152064 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    2010-06-29 20:36 . 2010-06-14 16:08 57856 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    2010-06-23 16:25 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2010-06-23 16:25 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2010-06-23 16:25 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
    2010-06-23 16:25 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2010-06-23 16:25 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2010-06-22 23:32 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2010-06-22 23:32 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2010-06-20 19:29 . 2010-06-20 19:29 -------- d-----w- c:\program files\iPod
    2010-06-20 19:29 . 2010-06-20 19:31 -------- d-----w- c:\program files\iTunes
    2010-06-20 19:24 . 2010-06-20 19:24 -------- d-----w- c:\program files\Bonjour
    2010-06-20 19:20 . 2010-06-20 19:20 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-18 00:48 . 2009-08-21 23:44 -------- d-----w- c:\users\Darlin\AppData\Roaming\LimeWire
    2010-07-18 00:44 . 2009-08-21 23:40 -------- d-----w- c:\program files\LimeWire
    2010-07-18 00:38 . 2009-09-05 23:39 48670 ----a-w- c:\programdata\nvModes.dat
    2010-07-18 00:36 . 2008-08-11 12:18 12 ----a-w- c:\windows\bthservsdp.dat
    2010-07-15 14:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-07-14 02:07 . 2009-08-14 18:56 -------- d-----w- c:\program files\Common Files\Adobe
    2010-07-12 13:25 . 2010-07-12 13:25 8 ----a-w- c:\users\Darlin\AppData\Roaming\vdnxlf.dat
    2010-07-12 02:07 . 2009-08-24 20:51 1356 ----a-w- c:\users\Darlin\AppData\Local\d3d9caps.dat
    2010-07-11 17:54 . 2009-12-30 23:37 -------- d-----w- c:\users\Darlin\AppData\Roaming\vlc
    2010-06-25 15:20 . 2008-08-11 10:56 62236 ----a-w- c:\windows\system32\perfh00C.dat
    2010-06-25 15:20 . 2008-08-11 10:56 19286 ----a-w- c:\windows\system32\perfc00C.dat
    2010-06-25 15:15 . 2009-08-24 21:08 -------- d-----w- c:\program files\Microsoft.NET
    2010-06-23 17:56 . 2009-08-22 01:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-06-20 19:29 . 2009-08-21 23:38 -------- d-----w- c:\program files\Common Files\Apple
    2010-06-14 17:32 . 2010-06-14 17:32 -------- d-----w- c:\programdata\LightScribe
    2010-06-11 17:22 . 2009-08-14 18:59 -------- d-----w- c:\programdata\Microsoft Help
    2010-06-08 21:01 . 2009-08-21 22:23 77944 ----a-w- c:\users\Darlin\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-06-08 17:24 . 2009-08-21 23:45 -------- d-----w- c:\users\Darlin\AppData\Roaming\Apple Computer
    2010-06-08 17:24 . 2009-08-21 23:38 -------- d-----w- c:\programdata\Apple
    2010-06-08 15:10 . 2009-12-02 20:45 -------- d-----w- c:\programdata\Norton
    2010-06-05 17:27 . 2010-02-15 18:56 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-06-02 22:46 . 2010-06-02 22:28 -------- d-----w- c:\users\Darlin\AppData\Roaming\BitComet
    2010-06-01 17:37 . 2009-10-03 03:00 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-26 17:06 . 2010-06-10 18:58 34304 ----a-w- c:\windows\system32\atmlib.dll
    2010-05-26 14:47 . 2010-06-10 18:58 289792 ----a-w- c:\windows\system32\atmfd.dll
    2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-05-16 01:16 . 2010-05-16 01:16 101376 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
    2010-05-16 01:16 . 2010-05-16 01:16 52224 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
    2010-05-04 19:15 . 2010-06-10 18:58 834048 ----a-w- c:\windows\system32\wininet.dll
    2010-05-04 18:37 . 2010-06-10 18:58 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-05-01 14:13 . 2010-06-10 18:57 2037248 ----a-w- c:\windows\system32\win32k.sys
    2010-04-30 02:15 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
    2010-04-23 14:13 . 2010-05-25 23:39 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-03-10 23:05 . 2009-10-03 04:02 59232800 --sha-w- c:\windows\System32\drivers\fidbox.dat
    2008-08-11 10:58 . 2008-08-11 10:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
    "Google Update"="c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-21 133104]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
    "pacqwen"="c:\users\Darlin\AppData\Roaming\nb-NOM.dll" [2010-07-10 88576]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
    "RogersServicepointAgent.exe"="c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" [2009-02-27 3228912]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
    "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]

    c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-7-31 139776]
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

    c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorUser"= 2 (0x2)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2"=hex(b):2f,48,75,21,55,e6,ca,01

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 133104]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
    S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-18 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-03 21:21]

    2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

    2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

    2010-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
    - c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]

    2010-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
    - c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.ca/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
    uInternet Settings,ProxyOverride = <local>;*.local
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe
    FF - ProfilePath - c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
    FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
    FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
    FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
    FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
    FF - plugin: c:\users\Darlin\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-FBSSA - c:\program files\SGPSA\ie3sh.exe
    HKLM-Run-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
    AddRemove-NSS - c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.3.34\InstStub.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-07-17 21:05
    Windows 6.0.6002 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    FBSSA = c:\program files\SGPSA\ie3sh.exe??es ???????owser Search\uninstalSGPU.exe??r????????m??_????????6??

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2010-07-17 21:09:19
    ComboFix-quarantined-files.txt 2010-07-18 01:09

    Pre-Run: 140,048,392,192 bytes free
    Post-Run: 139,231,453,184 bytes free

    - - End Of File - - C82E3F144D9A2D17DDCE6BB5455E7A83
    Last edited by ken545; 2010-07-18 at 03:42. Reason: Pasted CF log

  4. #4
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hi,

    Please just copy and paste the reports into this thread , its easier for me to see and analyze.

    CF logs are quite intense, just looking it over quickly it looks fairly good, what I would like you to do is to run both these programs and post the log for Malwarebytes, then reboot and run DDS and post a new DDS log please

    Remember with Vista you may have to right click the program and select RUN AS ADMINISTRATOR


    Please download ATF Cleaner by Atribune to your desktop.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
    Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.




    Please download Malwarebytes from Here or Here

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected .
    • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
    Post the report please
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  5. #5
    Member
    Join Date
    Jul 2010
    Posts
    47

    Default

    I ran ATF Cleaner and the Malwarebytes' scan. Here is the log.


    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4052

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 7.0.6002.18005

    18/07/2010 12:56:17 PM
    mbam-log-2010-07-18 (12-56-17).txt

    Scan type: Quick scan
    Objects scanned: 161010
    Time elapsed: 6 minute(s), 58 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 1
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\ProgramData\00412209 (Rogue.Multiple) -> Quarantined and deleted successfully.

    Files Infected:
    (No malicious items detected)

    _________________________________________________________________

    Here is the new DDS log.


    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Darlin at 13:10:18.48 on 18/07/2010
    Internet Explorer: 7.0.6002.18005
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1579 [GMT -4:00]

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\SMINST\BLService.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Users\Darlin\Desktop\dds.scr
    C:\Windows\system32\conime.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.ca/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
    uInternet Settings,ProxyOverride = <local>;*.local
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
    uRun: [Google Update] "c:\users\darlin\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [pacqwen] rundll32 "c:\users\darlin\appdata\roaming\nb-NOM.dll",UDPNTWWWQJ
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [JDK5SWFMZY] c:\users\darlin\appdata\local\temp\Ez1.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
    mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
    mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
    mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
    StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: {612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\xmlbar\youku downloader\YoukuDownloader(xmlbar).exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
    FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
    FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
    FF - plugin: c:\users\darlin\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-11 361808]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-11 193840]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\google\update\GoogleUpdate.exe [2009-9-3 133104]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== Created Last 30 ================

    2010-07-18 16:48:42 0 d-----w- c:\users\darlin\appdata\roaming\Malwarebytes
    2010-07-18 16:48:32 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-07-18 16:48:31 0 d-----w- c:\programdata\Malwarebytes
    2010-07-18 16:48:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-07-18 16:48:30 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-07-18 01:09:24 0 d-sh--w- C:\$RECYCLE.BIN
    2010-07-18 00:50:15 98816 ----a-w- c:\windows\sed.exe
    2010-07-18 00:50:15 77312 ----a-w- c:\windows\MBR.exe
    2010-07-18 00:50:15 256512 ----a-w- c:\windows\PEV.exe
    2010-07-18 00:50:15 161792 ----a-w- c:\windows\SWREG.exe
    2010-07-18 00:50:07 0 d-----w- C:\ComboFix
    2010-07-12 16:25:33 0 d-----w- c:\program files\Safer Networking
    2010-07-12 13:25:28 8 ----a-w- c:\users\darlin\appdata\roaming\vdnxlf.dat
    2010-07-12 03:08:05 255227926 ----a-w- c:\windows\MEMORY.DMP
    2010-07-12 01:05:43 0 d-----w- c:\program files\CCleaner
    2010-07-11 23:54:59 0 d-----w- c:\program files\TweetDeck
    2010-07-11 21:46:31 88 ----a-w- c:\windows\wininit.ini
    2010-07-11 21:16:36 0 d-----w- c:\programdata\Spybot - Search & Destroy
    2010-07-11 21:16:36 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-07-11 18:14:26 0 d-sh--w- c:\programdata\SMACCEEAV
    2010-07-10 03:20:48 88576 --sha-r- c:\users\darlin\appdata\roaming\nb-NOM.dll
    2010-07-01 03:07:30 0 d-----w- c:\users\darlin\dwhelper
    2010-06-23 16:25:13 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2010-06-23 16:25:13 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2010-06-23 16:25:13 297808 ----a-w- c:\windows\system32\mscoree.dll
    2010-06-23 16:25:13 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2010-06-23 16:25:13 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2010-06-22 23:32:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2010-06-22 23:32:16 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2010-06-20 19:29:53 0 d-----w- c:\program files\iPod
    2010-06-20 19:29:48 0 d-----w- c:\program files\iTunes
    2010-06-20 19:24:01 0 d-----w- c:\program files\Bonjour

    ==================== Find3M ====================

    2010-07-18 17:02:42 48670 ----a-w- c:\programdata\nvModes.dat
    2010-06-25 15:20:20 62236 ----a-w- c:\windows\system32\perfh00C.dat
    2010-06-25 15:20:20 19286 ----a-w- c:\windows\system32\perfc00C.dat
    2010-06-20 19:25:57 86016 ----a-w- c:\windows\inf\infstor.dat
    2010-06-20 19:25:57 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-06-20 19:25:56 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-06-01 17:37:48 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
    2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
    2010-05-18 20:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-05-18 20:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-05-04 19:15:20 834048 ----a-w- c:\windows\system32\wininet.dll
    2010-05-04 18:37:45 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-05-01 14:13:48 2037248 ----a-w- c:\windows\system32\win32k.sys
    2010-04-30 02:15:22 665600 ----a-w- c:\windows\inf\drvindex.dat
    2010-04-28 14:25:59 97420 ----a-w- c:\windows\fonts\leelawdb.ttf
    2010-04-27 21:28:06 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
    2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
    2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
    2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
    2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
    2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
    2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2010-03-10 23:05:08 59232800 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2008-08-11 10:58:25 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 13:12:01.78 ===============

    Thanks again for your help. Hope to hear from you soon.

  6. #6
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hello,

    You still have some things going on, lets do this, make sure you follow the instructions in the picture to check and uncheck whats shown

    Download the GMER Rootkit Scanner. Unzip it to your Desktop.

    Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
    • Double click GMER.exe.
    • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
    • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
      • IAT/EAT
      • Drives/Partition other than Systemdrive (typically C:\)
      • Show All (don't miss this one)

        Click the image to enlarge it
    • Then click the Scan button & wait for it to finish.
    • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
    • Save the log where you can easily find it, such as your desktop.
    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

    Please copy and paste the report into your Post.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  7. #7
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,964

    Default

    Nine pages of help. Thank you Ken.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •